1. Goal
Control default file and directory permissions for users, services, and login scripts.
2. Files and components involved
/etc/profile
/etc/login.defs
~/.bashrc
~/.profile
3. Operational flow
grep -n umask /etc/profile /etc/login.defs
set umask 027 in the required profiles
reopen shell
4. Operational verification
umask
touch /tmp/test-umask
mkdir /tmp/test-dir-umask
ls -ld /tmp/test-*
5. Practical notes
Apply these changes during a maintenance window and keep a backup of the original files for a quick rollback.
Tightening a policy without an alternative access path is the fastest way to lock out legitimate users as well.
Quick checklist
[ ] Backup or copy of the existing configuration completed
[ ] Files and commands updated as expected
[ ] Local test completed successfully
[ ] Logs or final output verified
[ ] Rollback procedure documented